ICS Cheat Sheet 2026
The 30 highest-yield ICS facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
75 questions
120 min time limit
70.00% to pass
- ISA/IEC 62443-3-3 Security Level 2 requires protection against which threat actor category? → Intentional violation using simple means by an entity with low motivation
- Which report type would BEST communicate recurring patch management gaps across multiple ICS sites to senior leadership? → A trend analysis report showing patch compliance rates over time with risk context
- What distinguishes a 'passive infrared' (PIR) sensor from an 'active infrared' sensor in ICS perimeter protection? → PIR sensors detect emitted body heat; active sensors transmit and receive IR beams
- What is the primary purpose of a demilitarized zone (DMZ) in an ICS network architecture? → To host historian servers accessible from both OT and IT networks
- During forensic evidence collection after an ICS incident, why is it important to document the chain of custody? → To preserve evidence integrity for potential legal proceedings or regulatory reporting
- Which threat actor group is historically associated with the CRASHOVERRIDE/Industroyer malware targeting electric grid ICS? → Sandworm (Russia)
- How should security incidents be handled? → Following an established incident response plan with documentation
- Which federal regulation requires cybersecurity programs for pipeline facilities, including ICS/SCADA systems? → TSA Pipeline Security Directives
- Why is documentation critical in compliance efforts? → Supports audits and accountability
- Under the NIST SP 800-53 control family, which control family is MOST directly applicable to ICS physical access to control rooms? → Physical and Environmental Protection (PE)
- Which factor is most important when determining treatment frequency? → Evidence-based clinical guidelines and patient response
- What is the PRIMARY security purpose of installing anti-ram bollards at the entrance of a critical ICS facility? → Stopping vehicle-borne improvised explosive device (VBIED) or ram-raid attacks
- An ICS facility uses wireless sensors for remote area monitoring. Which security control is MOST critical to implement for these devices? → Mutual authentication and encrypted communications between sensors and the gateway
- After containing an ICS cyber incident, what is the NEXT phase in the incident response lifecycle? → Eradication
- What is the impact of denial-of-service (DoS) attacks on ICS? → Loss of system availability
- When designing firewall rules for an ICS ESP, which rule-base philosophy is mandated by NERC CIP and recommended by ICS security frameworks? → Default-deny with explicit allow rules for required communications only
- What is the function of a 'dead man' alarm in a remote ICS field site? → Triggers when a field technician fails to check in within a defined interval
- How should a Industrial Control Systems Security professional handle situations beyond their expertise? → Refer to a qualified specialist and communicate transparently with the client
- Which framework provides a common language for managing cybersecurity risk? → NIST Cybersecurity Framework
- How should treatment protocols be modified for patients with comorbidities? → Adjust parameters based on individual risk factors and contraindications
- What is the primary purpose of maintaining accurate professional documentation? → To create a legal record of services and support continuity of care
- What is the recommended retention period guidance for ICS security incident records under NERC CIP standards? → 3 years
- What is the significance of professional networking in the Industrial Control Systems Security field? → It facilitates knowledge exchange, referrals, and collaborative problem-solving
- Which attack technique specifically targets ICS monitoring systems to make operators believe a process is running normally while malicious activity occurs? → False data injection (FDI) attack
- In ICS environments, what is the recommended approach when a vendor-issued patch cannot be applied immediately to a critical control system? → Apply compensating controls such as enhanced monitoring and network restrictions
- Which standard focuses specifically on control system cybersecurity? → ISA/IEC 62443
- An ICS organization must notify the Department of Homeland Security (DHS) CISA about a significant cyber incident within 72 hours under which regulation? → CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)
- What is the primary security risk of connecting an IP surveillance camera directly to an ICS control network without segmentation? → Cameras can serve as pivot points for attackers to reach control systems
- In OT security, which property is typically prioritized above the traditional IT security triad? → Availability
- During an ICS vulnerability assessment, a scanner detects an open port 102 on a device. What protocol and associated risk should the analyst investigate? → S7comm — susceptibility to Siemens PLC manipulation
Turn these facts into recall:
Was this helpful?